ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak
ShinyHunters Claims FBI Breach via Unpatched Oracle (TL-2026-2620) is a critical-severity data breach, first published 2026-09-22 and last reviewed 2026-09-27. It is attributed to ShinyHunters with medium confidence, affects Oracle PeopleSoft (PeopleTools), maps to 17 MITRE ATT&CK techniques (T1018, T1036.005, T1071.001), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-2620
- Threat ID
- TL-2026-2620
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-09-22
- Last reviewed
- 2026-09-27
- Attribution
- ShinyHunters
- Attribution confidence
- MEDIUM
- Motivation
- UNKNOWN
- Target sectors
- government administration, police - law enforcement, human-resources, corporate
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 24
- Updates
- 2026-09-27
Malware and tooling in ShinyHunters Claims FBI Breach via Unpatched Oracle
Malware and tooling: Clop, scattered lapsus$ hunters
Extortion collective ShinyHunters (Scattered Lapsus$ Hunters) claims it used a new, unpatched Oracle PeopleSoft zero-day to gain remote code execution on the FBI's apply.fbijobs.gov portal, pivot into FBI-managed AWS GovCloud infrastructure, and steal 2-3TB of PII/PHI on FBI employees, agents, and job applicants. The group defaced the portal, released a ~5,000-record sample independently spot-checked as partly accurate by 404 Media, and is demanding the FBI retract a May 2026 FLASH bulletin rather than paying a ransom; the FBI confirms it is investigating but has not confirmed a breach.
How ShinyHunters Claims FBI Breach via Unpatched Oracle works
On the night of Monday, September 21, 2026, the extortion collective ShinyHunters (operating as part of the loosely affiliated "Scattered Lapsus$ Hunters" / "The Com" cluster) told BleepingComputer and 404 Media it had exploited a previously unknown, unpatched remote-code-execution zero-day in Oracle PeopleSoft to compromise the FBI's public-facing Special Agent Applicant Portal (apply.fbijobs.gov). The group claims it used the initial foothold to move laterally into FBI-managed Amazon Web Services GovCloud infrastructure and exfiltrate 2-3TB of data spanning FBI Criminal Justice Information Services records, HR files, the FBI's Medlink medical/employee-health service, and job-applicant records covering current and former employees and prospective Special Agents.
ShinyHunters briefly defaced apply.fbijobs.gov with its trademark Umbreon (Pokemon) logo and a "seized by ShinyHunters" banner before the FBI took the portal offline. As proof, the group gave 404 Media a sample of roughly 5,000 purported employee records containing names, home addresses, phone numbers, and family-member details; 404 Media cross-referenced a subset of the phone numbers against OSINT tooling and found some corresponded to real individuals, including numbers associated with U.S. Department of Justice personnel. Neither the FBI, Oracle, nor AWS has confirmed a breach, a zero-day, or data theft; the FBI's only statement is that it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." No CVE has been assigned and no proof-of-concept or technical indicators for the underlying PeopleSoft flaw have been published.
Unusually for the group, ShinyHunters states the attack is "not financially motivated" and that it is not seeking a ransom but rather "coercion": it is demanding the FBI, addressed to Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, retract or correct a May 15, 2026 FBI FLASH/PSA bulletin that named ShinyHunters and Scattered Spider (tracked by Google as UNC6040/UNC6395) for a Salesforce data-theft extortion campaign and accused the group of harassment tactics including swatting and threats against victims' families. ShinyHunters also claims it is now exploiting the same new PeopleSoft zero-day against other, unnamed Fortune 500 organizations.
The incident sits inside an active feud between ShinyHunters and the Cl0p ransomware gang over ownership of a separate, already-patched Oracle flaw: CVE-2025-61882, an unauthenticated RCE in the BI Publisher Integration of Oracle E-Business Suite's Concurrent Processing component that Cl0p exploited as a zero-day from August 2025 before an October 2025 patch. Scattered Lapsus$ Hunters (including ShinyHunters) subsequently leaked the exploit and partial Oracle source code, asserting Cl0p had obtained "their" exploit without authorization. Days before the FBI claims, on September 19, 2026, ShinyHunters hijacked Cl0p's own dark-web leak site via an unauthenticated file-upload vulnerability in its Grav CMS, demanding an eight-figure cut of Cl0p's EBS extortion proceeds. ShinyHunters says it exfiltrated the leak site's source code, Grav CMS plugins, and server logs, and -- most significantly -- the private keys for Cl0p's Tor (.onion) hidden service, which it claims would let it operate Cl0p's dark-web leak address independently. ShinyHunters is also the actor Google Threat Intelligence Group/Mandiant track as UNC6240, which exploited a different, since-patched Oracle PeopleSoft PeopleTools RCE (CVE-2026-35273, patched out-of-band by Oracle on June 10, 2026) as a zero-day against more than 100 organizations, predominantly in education, in mid-2026 -- establishing a clear pattern of the group weaponizing unauthenticated Oracle enterprise-application RCEs as zero-days ahead of vendor disclosure. The zero-day claimed in this FBI incident is presented by ShinyHunters as a newly found, still-unpatched flaw distinct from CVE-2026-35273.
The CVE-2026-35273 campaign gives the clearest public technical picture of how UNC6240/ShinyHunters operates once inside a PeopleSoft environment, and is the closest available proxy for the mechanics of the still-undisclosed FBI zero-day. Per Rapid7 and Arctic Wolf incident-response telemetry, the actor exploited an unauthenticated SSRF-to-RCE chain via the /PSEMHUB/hub and /PSIGW/HttpListeningConnector Integration Gateway endpoints, using the SSRF to force outbound SMB connections capable of capturing Windows NetNTLM hashes; deployed MeshCentral remote-access agents disguised as Microsoft Azure binaries (e.g. meshagent64-azure-ops.exe) that beaconed to a C2 domain, azurenetfiles.net, masquerading as Azure over WSS/443; dropped .jsp web shells and XMLDecoder-based persistence under compromised PeopleSoft webserv/PSEMHUB.war paths; extracted credentials directly from PeopleSoft's psappsrv.cfg application-server configuration files; ran credential-spraying scripts and remote-system discovery to map web/app/batch server tiers for lateral movement; staged stolen data with zstd compression prior to exfiltration; and left a README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT marker on compromised hosts before publishing victim data to its leak site. This same actor's demonstrated, PeopleSoft-specific tradecraft is the basis for the additional ATT&CK techniques mapped below, since no independent technical telemetry has yet been published for the FBI-specific zero-day itself.
The claimed FBI compromise is also the latest in a string of 2026 FBI-adjacent incidents: in March 2026 the FBI disclosed a separate, unrelated "major incident" breach of its Digital Collection System Network (DCSNet) wiretap/surveillance infrastructure -- suspected to be Chinese state-sponsored and reportedly reached via a compromised ISP vendor -- and the Iran-linked "Handala" group separately compromised FBI Director Kash Patel's personal Gmail account and published stolen emails and photos. Those incidents are unrelated to ShinyHunters and are noted here only as target-profile context.
MITRE ATT&CK techniques used in TL-2026-2620
Discovery
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Command and Control
T1071.001 Web Protocols; T1219 Remote Access Tools
Credential Access
T1110.003 Password Spraying; T1187 Forced Authentication; T1552.001 Credentials In Files; T1552.004 Private Keys
Initial Access
T1190 Exploit Public-Facing Application
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage; T1560 Archive Collected Data
Impact
Persistence
Resource Development
T1588.005 Exploits; T1588.006 Vulnerabilities
Reconnaissance
Affected products and versions in ShinyHunters Claims FBI Breach via Unpatched Oracle
- Oracle — PeopleSoft (PeopleTools)
Vulnerable versions: unspecified -- claimed zero-day, no vendor advisory or CVE published as of 2026-09-22
Fixed in: none published as of 2026-09-22 - Federal Bureau of Investigation — FBIjobs.gov / apply.fbijobs.gov (Special Agent Applicant Portal)
Vulnerable versions: hosted service, no version applicable
Fixed in: taken offline by the FBI pending investigation - Amazon Web Services — AWS GovCloud (US) -- FBI-managed tenant
Vulnerable versions: hosted infrastructure, no version applicable
Remediation for ShinyHunters Claims FBI Breach via Unpatched Oracle
Patches
- No vendor patch or advisory exists yet for the specific zero-day claimed in this incident; monitor oracle.com/security-alerts for a new PeopleSoft/PeopleTools bulletin
- Apply Oracle's June 10, 2026 out-of-band Security Alert for CVE-2026-35273 (PeopleTools 8.61/8.62) if not already deployed
- Confirm the October 2025 Oracle patch for CVE-2025-61882 (E-Business Suite Concurrent Processing / BI Publisher Integration) is applied on any EBS instances
Immediate actions
- Audit and restrict internet-facing Oracle PeopleSoft / PeopleTools deployments; consider temporarily gating access behind a WAF or VPN pending vendor guidance on the newly claimed zero-day
- Rotate credentials and review access logs for HR, Medlink-equivalent health/benefits, and Criminal-Justice-Information-Services-adjacent integrations reachable from PeopleSoft application servers
- Review cloud (AWS GovCloud or equivalent) IAM, VPC flow, and CloudTrail logs for anomalous lateral movement originating from PeopleSoft/PeopleTools application hosts
- Enable defacement/file-integrity monitoring on public-facing recruitment and HR portals
Workarounds
- Restrict network reachability of PeopleSoft/PeopleTools administrative and integration HTTP endpoints to known-good IP ranges
- Increase logging verbosity and alerting on Oracle PeopleSoft HTTP request anomalies while a patch for the new flaw is unavailable
- Take non-essential public-facing PeopleSoft-hosted portals offline or place behind additional authentication pending vendor guidance
Longer-term hardening
- Confirm the June 10, 2026 Oracle out-of-band patch for CVE-2026-35273 is applied on all PeopleTools 8.61/8.62 instances as a baseline, since this actor has now targeted PeopleSoft twice in 2026
- Network-segment PeopleSoft/EBS application tiers from cloud management planes and identity providers to blunt RCE-to-cloud pivoting
- Establish an expedited patch/mitigation SLA for Oracle enterprise-application advisories given repeated zero-day use against EBS (CVE-2025-61882) and PeopleSoft (CVE-2026-35273) by this actor cluster in 2025-2026
- Extend Salesforce/SaaS OAuth-token and vishing defenses already built for the UNC6040/UNC6395 (ShinyHunters/Scattered Spider) FLASH advisory to cover Oracle on-prem/enterprise application exposure
Timeline of ShinyHunters Claims FBI Breach via Unpatched Oracle
- Threat actors, later attributed to Cl0p, begin exploiting CVE-2025-61882 as a zero-day against Oracle E-Business Suite Concurrent Processing / BI Publisher Integration, weeks ahead of a patch.
- Scattered Lapsus$ Hunters (including ShinyHunters) leak the CVE-2025-61882 exploit archive and partial Oracle source code, publicly asserting Cl0p obtained the exploit from them without authorization -- the origin of the ongoing ShinyHunters/Cl0p feud.
- FBI analysts detect abnormal log activity later attributed to a separate, unrelated 'major incident' breach of the FBI's Digital Collection System Network (DCSNet) wiretap/surveillance infrastructure via a compromised ISP vendor.
- Iran-linked group Handala publishes personal emails and photos it says were exfiltrated from FBI Director Kash Patel's personal Gmail account, an incident unrelated to ShinyHunters.
- The FBI publishes a FLASH/PSA bulletin naming ShinyHunters and Scattered Spider (tracked by Google as UNC6040/UNC6395) for a Salesforce data-theft extortion campaign and describing harassment tactics including swatting -- the bulletin ShinyHunters later demands be retracted.
- Oracle issues an out-of-band Security Alert patching CVE-2026-35273, a critical (CVSS 9.8) unauthenticated RCE in PeopleSoft PeopleTools 8.61/8.62; Google Threat Intelligence Group/Mandiant confirm ShinyHunters (UNC6240) had exploited it as a zero-day against 100+ organizations, mostly in education.
- ShinyHunters exploits an unauthenticated file-upload flaw in the Grav CMS powering Cl0p's dark-web leak site, seizes it, and demands an eight-figure share of Cl0p's Oracle EBS extortion proceeds.
- ShinyHunters claims it exploited a new, unpatched Oracle PeopleSoft zero-day for RCE against the FBI's apply.fbijobs.gov Special Agent Applicant Portal on Monday night, then moved laterally into FBI-managed AWS GovCloud infrastructure and exfiltrated an alleged 2-3TB of data.
- ShinyHunters publicly demands the FBI, addressed to Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, retract the May 15 FLASH report within one week, and claims it is now exploiting the same new PeopleSoft zero-day against other organizations including Fortune 500 companies.
- ShinyHunters defaces apply.fbijobs.gov with its Umbreon logo and a 'seized by ShinyHunters' message; 404 Media publishes a report including a verified-partly-accurate ~5,000-record employee sample; the FBI states it is investigating claims affecting FBIjobs.gov.
Update history for TL-2026-2620
- 2026-09-27 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s), 3 community-related indicator(s).
Sources cited for ShinyHunters Claims FBI Breach via Unpatched Oracle
- ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
- 'We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees
- Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data
- ShinyHunters claims FBI hack: 'This is NOT financially motivated'
- ShinyHunters claims FBI data theft, demands bureau retract cyber warning
- ShinyHunters escalates dispute with FBI; claims to have seized job applicants' site and acquired data
- ShinyHunters
- Oracle E-Business Suite Zero-Day Vulnerability (CVE-2025-61882)
- Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
- Oracle Security Alert Advisory - CVE-2026-35273
- Critical Oracle PeopleSoft Vulnerability Actively Exploited in ShinyHunters Campaign
- FBI warns of Scattered Spider and ShinyHunters attacks on Salesforce platforms
- ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
- Iran-linked hackers breach FBI Director Kash Patel's personal email, publish excerpts online
- FBI investigating hack on its wiretap and surveillance systems, report says
More in data breach
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour Extortion
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image Upload Server Exploit
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)
Detection coverage for TL-2026-2620
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2620 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2620
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.